Improper Restriction of Excessive Authentication Attempts in Etherpad - #VU151600
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to conduct password-guessing attacks.
The vulnerability exists due to improper restriction of excessive authentication attempts in the OIDC interaction login when processing failed login attempts. A remote attacker can submit repeated failed login attempts to conduct password-guessing attacks.